Scope
This policy covers the assets we operate ourselves.
- groupitcs.ca and its subdomains;
- virementfrauduleux.com;
- the server function that receives the site forms.
Legal information
If you find a flaw on our sites, we would rather hear it from you than from an attacker. This page sets out how to report it and what we commit to in return.
This policy covers the assets we operate ourselves.
Our clients systems fall outside this policy, even where we work on them under an engagement. Testing those systems requires written authorization from their owner.
Write to [email protected] with the asset concerned, a description of the flaw, the steps to reproduce it, the impact you estimate and, where possible, a capture or a trace. French and English are both fine.
If you would rather use an encrypted channel, ask for one in a first message without technical detail and we will open it.
We pay no bounty, but we do answer and we do fix.
These rules define the frame within which our commitment not to pursue you holds.
The following are closed without action, for lack of a workable demonstration.
A file compliant with RFC 9116 carries these details at the root of our domains, for the tools that look for it automatically.
Last revised: August 18, 2026